Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to append in a csv file only records which are unique from a certain point of time?

$
0
0
Hi, I need to append in a csv file only records which are unique from a certain date/time. The aim is to have only new events added to the csv file (and so the search would be scheduled) I used the `outputlookup append=true MyFile.csv`, but that appends results every time, including the previous one. Is there a way to put in the outputlookup comand criteria about other fields (such as _time or created_date...)? The only way I am thinking is fixing the timerange of the search which charges the csv file... Any suggestions? Thanks, Skender

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>